Hootoo manufactures portable travel routers and related networking appliances, with its vulnerability profile concentrated around the Trip Mate and Trip Mate Titan product lines and their embedded firmware. The observed weakness classes include buffer-boundary violations and OS command injection, reflecting the input-handling and privilege-execution demands of lightweight embedded networking software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hootoo over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20841CRITICAL HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp | Jun 11, 2019 | 9.8 | 55 | NO | NO |
CVE-2017-9026CRITICAL Stack buffer overflow in vshttpd (aka ioos) in HooToo Trip Mate 6 (TM6) firmware 2.000.030 and earlier allows remote unauthenticated attackers to control the program counter via a | May 17, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-9025MEDIUM Heap buffer overflow in vshttpd (aka ioos) in HooToo Trip Mate 6 (TM6) firmware 2.000.030 and earlier allows remote unauthenticated attackers to control the program counter via a s | May 17, 2017 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hootoo.
Media articles that mention a CVE ID that affects a product developed by Hootoo — matched by CVE ID, not by vendor name.